# Generated by iptables-save v1.4.4 on Mon Apr 5 14:11:09 2010
*mangle
:PREROUTING ACCEPT [1327088:897552922]
:INPUT ACCEPT [1730256:1273551057]
:FORWARD ACCEPT [1019078:599703844]
:OUTPUT ACCEPT [970438:681525041]
:POSTROUTING ACCEPT [2907956:2010042305]
COMMIT
# Completed on Mon Apr 5 14:11:09 2010
# Generated by iptables-save v1.4.4 on Mon Apr 5 14:11:09 2010
*nat
:PREROUTING ACCEPT [33686:2677324]
:POSTROUTING ACCEPT [487:29586]
:OUTPUT ACCEPT [14841:908605]
-A POSTROUTING -o vlan40 -j SNAT --to-source <внешний_ип>
COMMIT
# Completed on Mon Apr 5 14:11:09 2010
# Generated by iptables-save v1.4.4 on Mon Apr 5 14:11:09 2010
*filter
:INPUT DROP [3474:473080]
:FORWARD ACCEPT [69957:10084825]
:OUTPUT DROP [8:1420]
:allowed - [0:0]
:bad_packets - [0:0]
:bad_tcp_packets - [0:0]
:icmp_outbound - [0:0]
:icmp_packets - [0:0]
:tcp_inbound - [0:0]
:tcp_outbound - [0:0]
:udp_inbound - [0:0]
:udp_outbound - [0:0]
-A INPUT -i lo -j ACCEPT
-A INPUT -s 172.17.48.1/32 -i lo -j ACCEPT
-A INPUT -s 172.17.46.1/32 -i lo -j ACCEPT
-A INPUT -s 10.109.0.1/32 -i lo -j ACCEPT
-A INPUT -s 10.109.1.2/32 -i lo -j ACCEPT
-A INPUT -i tun0 -j ACCEPT
-A INPUT -i tun1 -j ACCEPT
-A INPUT -i tun3 -j ACCEPT
-A INPUT -i tun2 -j ACCEPT
-A INPUT -j bad_packets
-A INPUT -d 224.0.0.1/32 -j DROP
-A INPUT -s 10.110.0.0/24 -i vlan30 -j ACCEPT
-A INPUT -d 10.110.0.255/32 -i vlan30 -j ACCEPT
-A INPUT -i vlan40 -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -i vlan40 -p tcp -j tcp_inbound
-A INPUT -i vlan40 -p udp -j udp_inbound
-A INPUT -i vlan40 -p icmp -j icmp_packets
-A INPUT -m pkttype --pkt-type broadcast -j DROP
-A INPUT -j LOG --log-prefix "fp=INPUT:99 a=DROP "
-A FORWARD -p tcp -j bad_packets
-A FORWARD -s 10.110.0.48/32 -i vlan30 -o vlan40 -j ACCEPT
-A FORWARD -s 10.110.0.87/32 -i vlan30 -o vlan40 -j ACCEPT
-A FORWARD -s 10.110.0.34/32 -i vlan30 -o vlan40 -j ACCEPT
-A FORWARD -i vlan30 -p tcp -j tcp_outbound
-A FORWARD -i vlan30 -p udp -j udp_outbound
-A FORWARD -i vlan30 -p icmp -j icmp_outbound
-A FORWARD -i vlan40 -m state --state RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -j LOG --log-prefix "fp=FORWARD:99 a=DROP "
-A FORWARD -i vlan30 -o tun3 -j ACCEPT
-A FORWARD -d 10.110.0.2/32 -i tun3 -o vlan30 -j ACCEPT
-A FORWARD -i vlan30 -o tun0 -j ACCEPT
-A FORWARD -d 10.110.0.1/32 -i tun0 -o vlan30 -j ACCEPT
-A FORWARD -d 10.110.0.100/32 -i tun0 -o vlan30 -j ACCEPT
-A FORWARD -d 10.110.0.1/32 -i tun1 -o vlan30 -j ACCEPT
-A FORWARD -d 10.110.0.1/32 -i tun2 -o vlan30 -j ACCEPT
-A FORWARD -d 10.110.0.100/32 -i tun2 -o vlan30 -j ACCEPT
-A FORWARD -d 10.110.0.200/32 -i tun2 -o vlan30 -j ACCEPT
-A FORWARD -d 10.110.0.150/32 -i tun2 -o vlan30 -j ACCEPT
-A FORWARD -d 10.110.0.151/32 -i tun2 -o vlan30 -j ACCEPT
-A FORWARD -i vlan30 -o tun2 -j ACCEPT
-A OUTPUT -p icmp -m state --state INVALID -j DROP
-A OUTPUT -s 127.0.0.1/32 -j ACCEPT
-A OUTPUT -o lo -j ACCEPT
-A OUTPUT -s 172.17.48.1/32 -j ACCEPT
-A OUTPUT -s 172.17.46.1/32 -j ACCEPT
-A OUTPUT -s 10.109.0.1/32 -j ACCEPT
-A OUTPUT -s 10.109.1.2/32 -j ACCEPT
-A OUTPUT -s 10.110.0.254/32 -j ACCEPT
-A OUTPUT -o vlan30 -j ACCEPT
-A OUTPUT -o vlan40 -j ACCEPT
-A OUTPUT -j LOG --log-prefix "fp=OUTPUT:99 a=DROP "
-A allowed -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK SYN -j ACCEPT
-A allowed -p tcp -m state --state RELATED,ESTABLISHED -j ACCEPT
-A allowed -p tcp -j DROP
-A bad_tcp_packets -i vlan30 -p tcp -j RETURN
-A bad_tcp_packets -p tcp -m tcp ! --tcp-flags FIN,SYN,RST,ACK SYN -m state --state NEW -j LOG --log-prefix "fp=bad_tcp_packets:1 a=DROP "
-A bad_tcp_packets -p tcp -m tcp ! --tcp-flags FIN,SYN,RST,ACK SYN -m state --state NEW -j DROP
-A bad_tcp_packets -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG NONE -j LOG --log-prefix "fp=bad_tcp_packets:2 a=DROP "
-A bad_tcp_packets -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG NONE -j DROP
-A bad_tcp_packets -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,SYN,RST,PSH,ACK,URG -j LOG --log-prefix "fp=bad_tcp_packets:3 a=DROP "
-A bad_tcp_packets -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,SYN,RST,PSH,ACK,URG -j DROP
-A bad_tcp_packets -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,PSH,URG -j LOG --log-prefix "fp=bad_tcp_packets:4 a=DROP "
-A bad_tcp_packets -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,PSH,URG -j DROP
-A bad_tcp_packets -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,SYN,RST,ACK,URG -j LOG --log-prefix "fp=bad_tcp_packets:5 a=DROP "
-A bad_tcp_packets -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,SYN,RST,ACK,URG -j DROP
-A bad_tcp_packets -p tcp -m tcp --tcp-flags SYN,RST SYN,RST -j LOG --log-prefix "fp=bad_tcp_packets:6 a=DROP "
-A bad_tcp_packets -p tcp -m tcp --tcp-flags SYN,RST SYN,RST -j DROP
-A bad_tcp_packets -p tcp -m tcp --tcp-flags FIN,SYN FIN,SYN -j LOG --log-prefix "fp=bad_tcp_packets:7 a=DROP "
-A bad_tcp_packets -p tcp -m tcp --tcp-flags FIN,SYN FIN,SYN -j DROP
-A bad_tcp_packets -p tcp -j RETURN
-A icmp_outbound -p icmp -m icmp --icmp-type 8 -j ACCEPT
-A icmp_packets -p icmp -f -j LOG --log-prefix "fp=icmp_packets:1 a=DROP "
-A icmp_packets -p icmp -f -j DROP
-A icmp_packets -p icmp -m icmp --icmp-type 8 -j LOG --log-prefix "fp=icmp_packets:2 a=ACCEPT "
-A icmp_packets -p icmp -m icmp --icmp-type 8 -j ACCEPT
-A icmp_packets -p icmp -m icmp --icmp-type 11 -j ACCEPT
-A icmp_packets -p icmp -j RETURN
-A tcp_inbound -p tcp -m tcp --dport 21 -j allowed
-A tcp_inbound -p tcp -m tcp --dport 1988 -j allowed
-A tcp_inbound -p tcp -m tcp --dport 25 -j allowed
-A tcp_inbound -p tcp -m tcp --dport 110 -j allowed
-A tcp_inbound -p tcp -m tcp --dport 143 -j allowed
-A tcp_inbound -p tcp -m tcp --dport 3128 -j allowed
-A tcp_inbound -p tcp -j RETURN
-A tcp_outbound -p tcp -m tcp --dport 3274 -j allowed
-A tcp_outbound -p tcp -m tcp --dport 3279 -j allowed
-A tcp_outbound -p tcp -m tcp --dport 3389 -j allowed
-A tcp_outbound -p tcp -m tcp --dport 4899 -j allowed
-A tcp_outbound -p tcp -m tcp --dport 5222 -j allowed
-A tcp_outbound -p tcp -m tcp --dport 8585 -j allowed
-A tcp_outbound -p tcp -m tcp --dport 11758 -j allowed
-A tcp_outbound -p tcp -m tcp --dport 12758 -j allowed
-A tcp_outbound -p tcp -m tcp --dport 5190 -j allowed
-A tcp_outbound -p tcp -m tcp --dport 540 -j allowed
-A tcp_outbound -d 194.85.126.239/32 -p tcp -m tcp --dport 12345 -j allowed
-A tcp_outbound -p tcp -j RETURN
-A udp_inbound -p udp -m udp --dport 137 -j DROP
-A udp_inbound -p udp -m udp --dport 138 -j DROP
-A udp_inbound -p udp -m udp --dport 123 -j ACCEPT
-A udp_inbound -p udp -m udp --dport 53 -j ACCEPT
-A udp_inbound -p udp -m udp --dport 1195 -j ACCEPT
-A udp_inbound -p udp -m udp --dport 1196 -j ACCEPT
-A udp_inbound -p udp -m udp --dport 1202 -j ACCEPT
-A udp_inbound -p udp -m udp --dport 11201 -j ACCEPT
-A udp_inbound -p udp -j RETURN
-A udp_outbound -p udp -j ACCEPT
COMMIT
# Completed on Mon Apr 5 14:11:09 2010